SQL Injection Vulnerability in DataEase Data Visualization Software
CVE-2026-33084

8.7HIGH

Key Information:

Vendor

Dataease

Status
Vendor
CVE Published:
16 April 2026

What is CVE-2026-33084?

DataEase, an open-source data visualization platform, contains a SQL injection vulnerability in the sort parameter of the /de2api/datasetData/enumValueObj endpoint. This flaw occurs because the DatasetDataManage service layer directly incorporates user-supplied sort values into the SQL ORDER BY clause without proper validation. An authenticated attacker can exploit this vulnerability to inject arbitrary SQL commands, potentially leading to time-based blind SQL injection attacks. It is crucial for users of DataEase on versions 2.10.20 and earlier to upgrade to version 2.10.21 or later to mitigate this security risk.

Affected Version(s)

dataease < 2.10.21

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.